Error codes
unauthorized
HTTP status: 401
What happened
The bearer credential is missing or invalid. An API key may be malformed, revoked or unknown. A dashboard JWT may be expired, invalid or unverifiable with the configured signing keys.
How to fix
Send Authorization: Bearer st_live_... with an active key from the dashboard.
For dashboard requests, have the dashboard server obtain a fresh JWT and send it as the bearer
credential. A browser session cookie does not authenticate requests to the API. If fresh tokens
still fail, check the configured issuer and JWKS endpoint.
Source: docs/errors/unauthorized.md.